Bug #73936 [Com]: Certain special header() calls wrongly prevent connection from closing

From: Date: Fri, 05 Nov 2021 14:22:56 +0000
Subject: Bug #73936 [Com]: Certain special header() calls wrongly prevent connection from closing
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237568@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73936&edit=1 ID: 73936 Comment by: markamery at btinternet dot com Reported by: markamery at btinternet dot com Summary: Certain special header() calls wrongly prevent connection from closing Status: Assigned Type: Bug Package: Apache2 related Operating System: Ubuntu PHP Version: Irrelevant Assigned To: cmb Block user comment: N Private report: N New Comment: > > header('http/1.1 200 OK') > This is not valid according to RFC 7230, since the HTTP-name needs > to be upper case It's valid according to PHP's own docs at https://www.php.net/manual/en/function.header.php, which state that > There are two special-case header calls. The first is a header that starts with the string > "HTTP/" (case is not significant) ... For whatever reason, the design decision has been made by PHP to let you pass such strings in lowercase and then convert them to uppercase for you to make them spec-compliant. The really mysterious thing is that invoking that case-conversion behaviour somehow prevents this bug from exhibiting. Previous Comments: ------------------------------------------------------------------------ [2021-11-04 14:03:49] cmb@php.net > Unless Connection: keep-alive is specified in the request, the > connection should close once the PHP script finishes. For HTTP/1.1 requests, keep-alive is the default. Only HTTP/1.0 defaults to close.[1] > header('http/1.1 200 OK') This is not valid according to RFC 7230, since the HTTP-name needs to be upper case[2]. > http_response_code(200); I tentatively agree that this should behave identically to header('HTTP/1.1 200 OK'). I'll' have a closer look. [1] <https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Connection> [2] <https://datatracker.ietf.org/doc/html/rfc7230#appendix-B> ------------------------------------------------------------------------ [2017-01-14 18:38:54] markamery at btinternet dot com Description: ------------ Running under mod_php, calling header('HTTP/1.1 200 OK'); seems to prevent the connection from being closed once the PHP script finishes. This can be demonstrated by, for instance, hitting the script with ab (the Apache benchmark tool), which (unlike most HTTP clients, including browsers) only considers a request to have finished once the connection is closed, rather than when Content-Length bytes have been received. http://stackoverflow.com/q/34367115/1709587 describes this case in more detail. Bizarrely, header('http/1.1 200 OK'); does not have the same effect, despite producing a character-for-character identical HTTP response (as can be observed with curl -i --raw). Test script: --------------- <?php header('HTTP/1.1 200 OK'); Expected result: ---------------- Unless Connection: keep-alive is specified in the request, the connection should close once the PHP script finishes. In particular, the behaviour should be identical to other calls with the same meaning, like <?php http_response_code(200); or <?php header('http/1.1 200 OK') Actual result: -------------- The connection does not close, and the alternate scripts suggested above have different behaviours to the test script. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73936&edit=1

« previous php.bugs (#237568) next »